This is your work, valued
PayloadsAllTheThings. A list of useful payloads and bypass for Web Application Security and Pentest/CTF
★ 80kSSRFmap. Automatic SSRF fuzzer and exploitation tool
★ 3.6kInternalAllTheThings. Active Directory and Internal Pentest Cheatsheets
★ 2.3kGraphQLmap. GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes. - Do not use for illegal testing ;)
★ 1.7kHardwareAllTheThings. Hardware/IOT Pentesting Wiki
★ 915Wordpresscan. WPScan rewritten in Python + some WPSeku ideas
★ 653DamnWebScanner. Another web vulnerabilities scanner, this extension works on Chrome and Opera
★ 471SharpLAPS. Retrieve LAPS password from LDAP
★ 447Vulny-Code-Static-Analysis. Python script to detect vulnerabilities inside PHP source code using static analysis, based on regex
★ 425WHID_Toolkit. Simple script for the WHID injector - a rubberducky wifi
★ 120Nephelees. Néphélées (Νεφήλαι, Nephḗlai) : cloud nymphs greek - also NTDS cracking tool on Google Cloud
★ 38swisskyrepo.github.io. Source of swisskyrepo.github.io - Public
★ 31jsleak. Upgrading jsleak with a CI/CD and new rules
★ 17ygo-meta-deck. Deck analysis with OpenAI
★ 1CVE-2026-54121. Certighost POC
★ 274recon-skills. An evolving recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh
★ 1kHackBench. How effective are LLMs in identifying and exploiting security vulnerabilities?
★ 80gb10-glm-5.2. GLM-5.2-Int4-Int8 on 8x GB10 cluster
★ 22p3-loader. P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and staging location for shellcode injection into remote processes, without triggering common detection mechanisms.
★ 190MiniMax-M3-2x-DGX-Spark-36-tok-s. MiniMax-M3 (428B, no pruning) at 36 tok/s on 2× NVIDIA DGX Spark — W4A16 GPTQ + NVFP4 KV + EAGLE-3 speculative decoding on vLLM. Three serving lanes: speed / balanced / long-context.
★ 41GLM-5.2-QuantTrio-200K-4x-DGX-Spark--36tok-s. Recipe: GLM-5.2 (unpruned QuantTrio Int4-Int8Mix) at 200K ctx with MTP spec decode on a 4x NVIDIA DGX Spark (GB10) cluster
★ 72spark-hashcat. An optimized, containerized Hashcat API service engineered specifically for NVIDIA Grace Blackwell (GB10) systems running on ARM64
★ 5exo. Run frontier AI locally.
★ 47kpicsou-finance. Self-hosted personal finance dashboard Track bank accounts, brokerage, crypto, and net worth — all in one place.
★ 425sparkrun. sparkrun - launch, manage, and stop LLM inference workloads on NVIDIA DGX Spark systems
★ 414endpoint-ai-agent-abuse. EAA is a curated catalog of techniques and real-world cases involving abuse of local AI agents through their runtime, configuration, state, tools, and inherited authority.
★ 31tools. Tool schemas each model family uses.
★ 3caeruleus. Caeruleus is a Bluetooth Low Energy testing toolkit for Linux/BlueZ, implemented as a single Go binary. It covers the full interaction-to-assessment lifecycle
★ 38DeepSeek-v4-Flash-DSpark-Abliterated-Uncensored. DeepSeek V4 Flash DSpark Abliterated (Uncensored) — 2× DGX Spark serving
★ 23world-of-claudecraft. TypeScript
★ 2kexercises-dataset. 1,324-exercise fitness dataset — animation GIFs, 180×180 thumbnails, muscle-group & equipment data, and step-by-step instructions in 6 languages. The exercise data layer behind the LogPress app.
★ 18kSecorizonAI. A fully automated terminal-native AI shell built for security professionals.
★ 53strix. Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
★ 45kProteus. Rust C2 agent for Mythic that produces polymorphic shellcode: per-build function shuffle + ChaCha20-encrypted data sections; no_std/no_main agent, PEB-walked APIs, WinHTTP comms.
★ 75pentest-copilot. Pentest Copilot is an AI-powered browser based ethical hacking assistant tool designed to streamline pentesting workflows.
★ 1.1kBoxPwnr. A modular framework for benchmarking LLMs and agentic strategies on security challenges across HackTheBox, TryHackMe, PortSwigger Labs, Cybench, picoCTF and more.
★ 435autopentest-ai. Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.
★ 201litellm-agent-control-plane. 1 place to call all your agents - OpenCode, Hermes, Claude Managed Agents, Cursor Agents API, DeepAgents.
★ 1.2komnigent. Omnigent is an open-source AI agent framework and meta-harness: orchestrate Claude Code, Codex, Cursor, Pi, and custom agents — swap harnesses without rewriting, enforce policies and sandboxing, and collaborate in real time from any device.
★ 7.9kClaude-BugHunter. A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes, plus enterprise identity + infrastructure attack matrices.
★ 3.2kcoraza. OWASP Coraza WAF is a golang modsecurity compatible web application firewall library
★ 3.7kgrimoire. Offensive knowledge, offline. One search box for every playbook.
★ 191claude-bug-bounty. AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude Code.
★ 4.1kclaude-code-security-review. An AI-powered security review GitHub Action using Claude to analyze code changes for security vulnerabilities.
★ 5.7krota. A high-performance proxy rotation engine with automated IP management and real-time health monitoring
★ 560npxconfuse. npx confusion vulnerability scanner
★ 12CAPSlock. CAPSlock is an offline Conditional Access (CA) analysis tool built on top of a roadrecon database. It helps defenders, auditors, and red teams understand how Conditional Access policies actually behave, not just how they are configured.
★ 93ironcurtain. A secure* runtime for autonomous AI agents. Policy from plain-English constitutions. (*https://ironcurtain.dev)
★ 566lean-ctx. Control what your AI can see. LeanCTX (Lean Context) is the context intelligence layer for AI agents — one local Rust binary that decides what they read, remembers what they learn, guards what they touch, and proves what they save. 60–90% fewer tokens as the receipt. 76 MCP tools, 30+ agents, local-first.
★ 3.4kOpenAlice. Your one-person Wall Street. An AI trading agent covering equities, crypto, commodities, forex, and macro — from research through position entry, ongoing management, to exit.
★ 6.3kaudit. An 8-stage vulnerability-discovery agent.
★ 787cryptex-oss. Open-source LLM red-teaming technique toolkit (162 transforms, 36 mutators, 25 tool surfaces). MIT.
★ 340Claude-Red. claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface — from SQLi to shellcode, EDR evasion to exploit development.
★ 2.8kvigolium. Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision
★ 933Webwright. A simple SWE style browser agent framework that achieves SOTA results on long horizon web tasks.
★ 5.8ktaskqueue-mcp. MCP tool for exposing a structured task queue to guide AI agent workflows. Great for taming an over-enthusiastic Claude.
★ 71relay_bible. Technical Reference to multiple relay techniques
★ 191skills. Public repository for Agent Skills
★ 165kpocsmith. Autonomous Windows POC developer from patchwatch diff reports
★ 66patchwatch. A local tool for ingesting Windows Patch Tuesday CVEs, diffing patched binaries with Ghidriff and surfacing LLM-generated security analysis through a browser UI
★ 55workshop. Give your coding agent the power to write and run agent evals.
★ 943claude-for-legal. A suite of plugins for legal workflows
★ 8.9kcodex-attack. An Advanced Cyber Plugin for Codex
★ 39Rapid-MLX. The fastest local AI engine for Apple Silicon. 4.2x faster than Ollama, 0.08s cached TTFT, 100% tool calling. 17 tool parsers, prompt cache, reasoning separation, cloud routing. Drop-in OpenAI replacement. Works with Claude Code, Cursor, Aider.
★ 3.4kmlx-serve. Native LLM inference server for Apple Silicon. OpenAI + Anthropic API compatible. No Python. Includes MLX Core macOS app with chat, agent mode, and tool calling.
★ 385ida-mcp-rs. Headless IDA Pro MCP Server
★ 673paperasse. 🇫🇷 Skills pour agents IA spécialisés dans la bureaucratie française : Comptable, Notaire, ...
★ 2.3kfloci. Light, fluffy, and always free - The AWS Local Emulator alternative
★ 18kopencode-studio. web GUI for securely managing local OpenCode configuration
★ 689skills. Skills for Real Engineers. Straight from my .agents directory.
★ 194kpentestagent. PentestAgent is an AI agent framework for black-box security testing, supporting bug bounty, red-team, and penetration testing workflows.
★ 2.8kladder. Selfhosted alternative to 12ft.io. and 1ft.io. Proxy to remove CORS headers and modify HTML
★ 8.8kfriday-studio. Agent Harness Platform — shareable workspaces, MCP tools, skills, memory, and cron/webhook automations. Self-hosted and transparent.
★ 98dirtyfrag. C
★ 5ksure. The personal finance app for everyone (by everyone)
★ 9.2kcamoufox-browser-cli. CLI-first browser automation powered by Camoufox, with optional MCP support
★ 8camoufox. 🦊 Anti-detect browser
★ 11kskills. Claude Code plugins and Codex skills from Calif.io for AI-assisted security research and code auditing
★ 59claude-code-analysis. We read all 512K lines of Claude Code's accidentally exposed source. 82 docs, 15 diagrams, every subsystem mapped — from the hidden YOLO safety classifier to multi-agent swarms.
★ 124weird_proxies. Reverse proxies cheatsheet
★ 1.9kotto-support. An implementation of a vulnerable MCP server using mcp-go
★ 18ctf-skills. Agent skills for solving CTF challenges - web exploitation, binary pwn, crypto, reverse engineering, forensics, OSINT, and more
★ 2.9kkimaki. all opencode features deeply integrated inside Discord. each project is a channel. each session a thread
★ 1.3kwarp. Warp is an agentic development environment, born out of the terminal.
★ 64kawesome-claude-code-subagents. A collection of 100+ specialized Claude Code subagents covering a wide range of development use cases
★ 24kopencode-sdk-python. Python
★ 262GhostReconRev. Complete revamp of GhostRecon and FrontRecon into a single pipeline boosted by AI and DAST tools.
★ 1orca. Orca is the ADE for working with a fleet of parallel agents. Run any coding agent with your own subscription. Available on desktop, mobile and VPS.
★ 32kkCaddy. Malleable Caddy Redirector
★ 17skills. Agent Skills for Google products and technologies
★ 15kagentflow. Orchestrate thousands of agents and harnesses as a graph programatically
★ 1.4kOutpacket. This cheatsheet maps common impacket workflows to their modern alternatives
★ 302ghostsurf. NTLM HTTP relay tool with SOCKS proxy for browser session hijacking
★ 180rainbowcrackalack. Rainbow table generation & lookup tools. Make Rainbow Tables Great Again!
★ 236clearwing. Python
★ 1kOpenKB. OpenKB: Open LLM Knowledge Base
★ 3.2ksmokedmeat. A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.
★ 371gopacket. A complete Go port of Impacket - 63 CLI tools and 24 libraries for Windows & Active Directory protocol attacks, compiled to a single dependency-free binary.
★ 701GhidrAssistMCP. An native MCP server extension for Ghidra
★ 686open-agents. An open source template for building cloud agents.
★ 5.8kcve-mcp-server. Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan, VirusTotal, and more.
★ 1.1khankweave-runtime. Runtime for long-horizon agents
★ 133camofox-browser. Stealth headless browser for AI agents — bypass Cloudflare, bot detection, and anti-scraping. Drop-in Puppeteer/Playwright replacement.
★ 8.2kobsidian-second-brain. Persistent memory for Claude Code and 6 other CLI agents, stored as plain markdown in your Obsidian vault. Stop re-explaining your projects, decisions and people every session. 45 commands: hybrid semantic search, self-rewriting notes, key-less web research, and scheduled agents that maintain the vault while you sleep.
★ 3.7kgbrain. Garry's Opinionated OpenClaw/Hermes Agent Brain
★ 27kopencode-qwencode-oauth. Qwen OAuth authentication plugin for OpenCode with multi-account rotation and API translation
★ 50datagouv-mcp. Official data.gouv.fr Model Context Protocol (MCP) server that allows AI chatbots to search, explore, and analyze datasets from the French national Open Data platform, directly through conversation.
★ 1.6kcaveman. 🪨 why use many token when few token do trick — Claude Code skill that cuts 65% of tokens by talking like caveman
★ 94kWaza. 🥷 Engineering habits you already know, turned into skills Claude can run.
★ 6.7kKeychron-Keyboards-Hardware-Design. Industrial design files for Keychron keyboards and mice. 100+ models with CAD assets in STEP, DXF, DWG, and PDF. Source-available, with commercial use allowed for original compatible accessories within the license terms.
★ 3.6krtk. CLI proxy that reduces LLM token consumption by 60-90% on common dev commands. Single Rust binary, zero dependencies
★ 74kClawTeam. "ClawTeam: Agent Swarm Intelligence" (One Command → Full Automation)
★ 5.5ksuperpowers. An agentic skills framework & software development methodology that works.
★ 263kreaper. Live validation proxy tool for testing web app vulnerabilities
★ 878GhidrAssist. An LLM extension for Ghidra to enable AI assistance in RE.
★ 686code-review-prompts. A collection of useful prompts and system prompts for security-oriented code reviews
★ 37SilentNimvest. Nim implementation for sud0Ru's Credential Dumping from SAM/SECURITY Hives Method (a.k.a. SilentHarvest)
★ 107graphthulhu. MCP server that gives AI full access to your Logseq or Obsidian knowledge graph. 39 tools for navigation, search, analysis, writing, decisions, journals, flashcards, and whiteboards.
★ 170bore. 🕳 bore is a simple CLI tool for making tunnels to localhost
★ 11kmodelcontextprotocol. Specification and documentation for the Model Context Protocol
★ 8.7kqmd. mini cli search engine for your docs, knowledge bases, meeting notes, whatever. Tracking current sota approaches while being all local
★ 28kllm-sast-scanner. A SAST skill that gives AI coding agents structured vulnerability detection across 34 vulnerability classes.
★ 273agentic. An agentic workflow tool that provides context engineering support for opencode
★ 607opencode-quota. OpenCode quota & tokens usage with zero context window pollution. Supports OpenCode Go, Cursor, GitHub Copilot, OpenAl (Plus/Pro), Kimi Code, Alibaba Coding Plan, Chutes Al, Google Antigravity, Z.ai Coding Plan and more.
★ 776oh-my-openagent. omo/lazycodex: The coding agent for tokenmaxxers;the one and only agent harness for complex codebases. For your Codex, for your OpenCode
★ 67koh-my-opencode-slim. Lean, fine tuned Opencode multi agent suite · Mix any models · Auto delegate tasks
★ 7.4kmcp-security-hub. A growing collection of MCP servers bringing offensive security tools to AI assistants. Nmap, Ghidra, Nuclei, SQLMap, Hashcat and more.
★ 751opium. Load balancer for your Claude Pro/Max subscription accounts.
★ 16VibeHacking. TypeScript
★ 27caido-mcp-server. MCP server for Caido proxy integration. Enables AI assistants like Claude Code to browse, analyse, and interact with HTTP traffic.
★ 97BAADTokenBroker. PowerShell
★ 128CLIProxyAPI. Wrap Antigravity, ChatGPT Codex, Claude Code, Grok Build as an OpenAI/Gemini/Claude/Codex compatible API service, allowing you to enjoy the free Gemini 3.1 Pro, GPT 5.5, Grok 4.3, Claude model through API
★ 45kLifeOS. ⛰️A General Hill-climbing AI harness that helps you move from Current State to Ideal State in both Life and Work.
★ 17kllmchainhunter. Leveraging LLM to generate Java deserialization chains
★ 87deepagents. The batteries-included agent harness.
★ 27kkong. The world's first agentic reverse engineer.
★ 1.1kheretic. Fully automatic censorship removal for language models
★ 27kpromptfoo. Test your prompts, agents, and RAGs. Red teaming/pentesting/vulnerability scanning for AI. Compare performance of GPT, Claude, Gemini, DeepSeek, and more. Simple declarative configs with command line and CI/CD integration. Used by OpenAI and Anthropic.
★ 24kAUTOCTF. AI-powered CTF automation platform utilizing GPT models.
★ 31pinchtab. High-performance browser automation bridge and multi-instance orchestrator with advanced stealth injection and real-time dashboard.
★ 9.7kEbka-Caido-AI. AI-powered assistant that integrates seamlessly with Caido
★ 80deer-flow. An open-source long-horizon SuperAgent harness that researches, codes, and creates. With the help of sandboxes, memories, tools, skill, subagents and message gateway, it handles different levels of tasks that could take minutes to hours.
★ 78kopenai-agents-python. A lightweight, powerful framework for multi-agent workflows
★ 28kbeads. Beads - A memory upgrade for your coding agent
★ 26kacquiscan. Extract acquisition and subsidiary information from SEC filings
★ 10AutoIt-Ripper. Extract AutoIt scripts embedded in PE binaries
★ 241skills. 🤹 Caido AI Skills
★ 249nerva. Fast service fingerprinting CLI for 170+ protocols (TCP/UDP/SCTP) - built by Praetorian
★ 319jxscout. jxscout superpowers JavaScript analysis for security researchers
★ 473titus. High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.
★ 652lsawhisper-bof. A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without touching LSASS process memory.
★ 297voicebox. The open-source AI voice studio. Clone, dictate, create.
★ 47kclaudleak. Hunt for AI coding artifacts containing secrets.
★ 57mimikatz-missing-manual. The Mimikatz Missing Manual
★ 461ClickOnceBlobber. Weaponize signed .NET ClickOnce applications for initial access by hijacking a dependency DLL via AppDomainManager injection and loading a C# port of ProxyBlob Agent.
★ 168sic. A tool to perform Sequential Import Chaining
★ 290CobaltStrike-Linux-Beacon. Proof of Concept (PoC) implant for creating custom Cobalt Strike Beacons
★ 218SCOMDecrypt. SCOMDecrypt is a tool to decrypt stored RunAs credentials from SCOM servers
★ 130shannon. Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
★ 46kzkar. ZKar is a Java serialization protocol analysis tool implement in Go.
★ 653tldfinder. A streamlined tool for discovering private TLDs for security research.
★ 324RelayKing-Depth. Dominate the domain. Relay to royalty.
★ 339draw2. DRAW 2 (Detect and Recognize A Wide range of cards) Object detector trained to detect Yu-Gi-Oh! cards in all types of images, and in particular in dueling images.
★ 77skills. Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows
★ 6.3kopenclaw. Your own personal AI assistant. Any OS. Any Platform. The lobster way. 🦞
★ 384kswarmer. A tool to convert windows registry export files into windows hive files that can be used to replace NTUSER.MAN
★ 151adeleg. Active Directory delegation management tool
★ 525CVE-2025-33073. PoC Exploit for the NTLM reflection SMB flaw.
★ 711crapsecrets. A library for detecting known secrets across many web frameworks
★ 22Metrolist. YouTube Music client for Android
★ 11kdocker-android. 🤖 A minimal and customizable Docker image running the Android emulator as a service.
★ 7.1ksemgrep-rules. Java
★ 246TokenSmith. TokenSmith generates Entra ID access & refresh tokens on offensive engagements. It is suitable for both covert adversary simulations and penetration tests with the tokens generated working out of the box with many popular Azure post exploitation tools.
★ 416TokenFlare. Serverless AITM Simulation Framework for Entra ID and M365
★ 241NextRce. React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)
★ 255elastic-container. Stand up a simple Elastic container with Kibana, Fleet, and the Detection Engine
★ 567SharpSCOM. A C# utility for interacting with SCOM
★ 100Adrenaline. C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.
★ 312react2shell-scanner. High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)
★ 2.5kNext.js-RSC-RCE-Scanner-CVE-2025-66478. A command-line scanner for batch detection of Next.js application versions and determining if they are affected by CVE-2025-66478 vulnerability.
★ 430CVE-2025-55182. Explanation and full RCE PoC for CVE-2025-55182
★ 1.4kFlipperAmiibo. Made to be used with Flipper just drag the folder into NFC
★ 3.6kawesome-nanobanana-pro. 🚀 An awesome list of curated Nano Banana pro prompts and examples. Your go-to resource for mastering prompt engineering and exploring the creative potential of the Nano banana pro(Nano banana 2) AI image model.
★ 10kextensions. Extension repository for Mihon and variants
★ 15kmihon. Free and open source manga reader for Android
★ 22kasm-lessons. FFmpeg Assembly Language Lessons
★ 12kNX_Firmware. Firmware for the Nintendo Switch
★ 4.3kShareHound. A python tool to map the access rights of network shares into a BloodHound OpenGraphs easily
★ 310secpipe. MCP server for AI-driven security pipelines
★ 803force-push-scanner. Scan for secrets in dangling commits on GitHub using GH Archive data.
★ 484Musify. Unlock the full potential of music: Stream effortlessly with one app!
★ 4.1kSetZeroSync. Python
★ 13Titanis. Windows protocol library, including SMB and RPC implementations, among others.
★ 810supervision. We write your reusable computer vision tools. 💜
★ 48kWSPCoerce. PoC to coerce authentication from Windows hosts using MS-WSP
★ 305Client-Checker. PowerShell
★ 205Sir-Reginald-Buys-The-Dips. A frightfully intelligent algorithmic trading automaton of noble birth. Sir Reginald's prime directive: to acquire undervalued assets post-haste. Tally-ho, to the moon!
★ 44GPOHound. Offensive GPO dumping and analysis tool that leverages and enriches BloodHound data
★ 413wstunnel. Tunnel all your traffic over Websocket or HTTP2 - Bypass firewalls/DPI - Static binary available
★ 6.9kioctlance. A tool that is used to hunt vulnerabilities in x64 WDM drivers
★ 469crescendoattacker. Simple implementation of prompt generation and AI model red teaming code for crescendo attacks
★ 26GhydraMCP. Ghidra plugin exposing a HATEOAS REST API, with a Python MCP bridge and CLI for AI-assisted reverse engineering: multi-instance decompilation, disassembly, and binary analysis. Supports Ghidra 11.x and 12.x.
★ 284turnt. A tool designed for smuggling interactive command and control traffic through legitimate TURN servers hosted by reputable providers such as Zoom.
★ 430pyghidra-mcp. Python Command-Line Ghidra MCP
★ 391codex. Lightweight coding agent that runs in your terminal
★ 102kHF-Agents-Course-Notes. My Notes from Hugging Face AI Agents Course
★ 20hexstrike-ai. HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capabilities.
★ 11kgpoParser. gpoParser is a tool designed to extract and analyze configurations applied through Group Policy Objects (GPOs) in an Active Directory environment.
★ 367buttercup. Buttercup finds and patches software vulnerabilities
★ 1.6kCVE-2025-30406. CVE-2025-30406 ViewState Exploit PoC
★ 90qwen-code. An open-source AI coding agent that lives in your terminal.
★ 26kgssapi-abuse. A tool for enumerating potential hosts that are open to GSSAPI abuse within Active Directory networks
★ 188MSSQLHound. Go (formerly PowerShell) collector for adding MSSQL attack paths to BloodHound with OpenGraph
★ 338hashcrafter. A powerful *vibe coded* command-line tool for generating all possible combinations of text strings and testing them against specified hashes.
★ 11